Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, an authenticated user can read any task comment by ID, regardless of whether they have access to the task the comment belongs to, by substituting the task ID in the API URL with a task they do have access to. Version 2.2.0 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, an authenticated user can read any task comment by ID, regardless of whether they have access to the task the comment belongs to, by substituting the task ID in the API URL with a task they do have access to. Version 2.2.0 fixes the issue. | |
| Title | Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-24T17:14:22.348Z
Reserved: 2026-03-18T21:23:36.676Z
Link: CVE-2026-33313
Updated: 2026-03-24T17:14:11.342Z
Status : Undergoing Analysis
Published: 2026-03-24T15:16:35.073
Modified: 2026-03-24T15:53:48.067
Link: CVE-2026-33313
No data.
OpenCVE Enrichment
No data.